From a4e85856628930c4a349bfc8b2a18af5a9beda33 Mon Sep 17 00:00:00 2001 From: Thibault Le Ouay Ducasse Date: Tue, 22 Sep 2026 11:27:42 +0200 Subject: [PATCH] ci: don't let one failed build leg block publishing the other services The merge job depended on the whole build matrix, so a single failed service/arch leg skipped tag publication for every service. Run merge with !cancelled() and fail a service's own merge when it doesn't have both digests, so a partial (single-arch) manifest is never tagged. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/docker-publish.yml | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 38e4b4a0..ca0bb160 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -171,10 +171,12 @@ jobs: # Combine the per-arch digests into a multi-arch manifest list carrying the # real tags, then generate the SBOM from that manifest. + # Runs even if some `build` legs failed so one broken service does not block + # publishing the others; a service missing a digest fails its own merge below. merge: runs-on: ubuntu-latest needs: [prepare, build] - if: needs.prepare.outputs.services != '[]' + if: ${{ !cancelled() && needs.prepare.outputs.services != '[]' }} timeout-minutes: 15 permissions: contents: read @@ -224,6 +226,13 @@ jobs: id: manifest working-directory: /tmp/digests run: | + # Never publish a partial (single-arch) manifest under the real tags. + count=$(ls | wc -l) + if [ "$count" -ne 2 ]; then + echo "::error::expected 2 digests (amd64 + arm64) for ${{ matrix.service }}, found $count" + ls -la + exit 1 + fi docker buildx imagetools create \ $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \ $(printf '${{ env.IMAGE }}@sha256:%s ' *) -- 2.51.2